WSLProxy WAF · efficacy lab

WAF Efficacy Lab —

Fire every shipped WAF test case (GET and POST) at this host and see, live, what the WAF stops — matched rule, violation code and support id. The lab tests the host that serves it (same-origin is the only way a browser can read a WAF block); use the switch to flip between the protected and unprotected host.

— Click Run all to test this host.
AttackMethodExpect StatusResultRule / violationVerdict

Same-origin only: a browser can read a WAF 403 block and the x-waf-* headers just for the host serving this page. One case (scanner User-Agent) can't run in-browser because scripts may not set User-Agent — run it with curl. For the machine-readable matrix and the open-host control, use test_waf_live.py. Generated by gen_waf_lab.py from test_waf_live.py.